200-201 Security Policies and Procedures Practice Question
An organization is developing an Acceptable Use Policy (AUP). Which of the following topics is typically covered in an AUP?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Prohibition of using company resources for illegal activities
An AUP defines acceptable use of IT resources, including prohibiting unauthorized access, personal use guidelines, and security responsibilities.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Password complexity requirements
Why it's wrong here
Password complexity requirements sit in the password or authentication policy, which defines credential construction rules. An AUP governs acceptable employee use of organisational systems. Password rules are tempting because they are security controls, but they specify credential mechanics rather than permitted user behaviour on assets.
- ✗
Incident reporting procedures
Why it's wrong here
Incident reporting procedures belong in the incident response plan, which defines detection, escalation and containment steps. An AUP governs acceptable employee use of organisational systems. Reporting procedures are tempting because they involve user duties, but the AUP addresses acceptable use, not the response workflow after an incident.
- ✗
Data classification levels
Why it's wrong here
Data classification levels belong in a data handling or classification policy, which assigns sensitivity labels and handling rules. An AUP governs acceptable employee use of organisational systems and assets. Classification is tempting because both are security policies, but the AUP addresses user behaviour, not data labelling.
- ✓
Prohibition of using company resources for illegal activities
Why this is correct
An Acceptable Use Policy defines permitted and forbidden employee behaviour on organisational systems. Prohibiting use of company resources for illegal activities is a core AUP clause, establishing legal boundaries and enabling disciplinary action, directly satisfying the typical AUP content requirement.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.